• Windows 10 machines constantly pinging Israel IPs

    2
    0 Votes
    2 Posts
    457 Views
    NogBadTheBadN

    @azdeltawye said in Windows 10 machines constantly pinging Isreal IPs:

    185.77.248.89

    AS details for AS58018 :-

    aut-num: AS58018
    as-name: NETSTYLE2
    org: ORG-NAL9-RIPE
    import: from AS43945 accept ANY
    export: to AS43945 announce AS-NETSTYLE
    admin-c: DUMY-RIPE
    tech-c: DUMY-RIPE
    member-of: AS-NETSTYLE
    status: ASSIGNED
    mnt-by: RIPE-NCC-END-MNT
    mnt-by: EC42500-MNT
    created: 2017-01-02T14:57:40Z
    last-modified: 2018-09-04T11:56:16Z
    source: RIPE
    remarks: ****************************
    remarks: * THIS OBJECT IS MODIFIED
    remarks: * Please note that all data that is generally regarded as personal
    remarks: * data has been removed from this object.
    remarks: * To view the original object, please query the RIPE Database at:
    remarks: * http://www.ripe.net/whois
    remarks: ****************************

    IPv4 subnets for AS58018 :-

    185.77.248.0/24

    IPv6 subnets for AS58018 :-

    2a00:55a0:3::/48

    Wednesday, 9 December 2020 at 21:39:06 Greenwich Mean Time

  • Pfblocker NAT rules.

    2
    0 Votes
    2 Posts
    1k Views
    K

    I'm having the same issue with pfBlocker and NAT rules. I have no issues adding white-list rules for my devices that are on a directly routed subnet. But trying to figure out how to handle an allow rule for an existing NAT rule is causing issues.

    Have you found any solution yourself as of yet?

  • pfBlockerNG IPV4 problem

    Moved
    18
    0 Votes
    18 Posts
    1k Views
    BBcan177B

    @rtkluttz said in pfBlockerNG IPV4 problem:

    Upgrade to pfBlockerNG-devel.

  • pfBlockerNG-devel 3.0.0_3 DNSBL alerts no longer showing source IP

    9
    0 Votes
    9 Posts
    1k Views
    P

    I am running Version 2.4.5-RELEASE-p1 and pfBlocker DEVEL 3.0.0_3

  • Revert to latest 2.2.5 dev

    11
    0 Votes
    11 Posts
    923 Views
    kiokomanK

    @chpalmer
    no it's not... 🤢
    we are going out of topic ... but I prefer cappuccino when I wake up
    https://www.youtube.com/watch?v=yWKu8ammTlA

  • DSNBL out of sync

    5
    0 Votes
    5 Posts
    632 Views
    P

    @bbcan177
    that worked. thanks a lot.

  • DNSBL service unable to enable

    8
    0 Votes
    8 Posts
    1k Views
    T

    @trewflight48
    gonna watch this video I guess I have alot to learn still.

    How To Setup ACME, Let's Encrypt, and HAProxy HTTPS offloading on pfsense.

  • pfBlockerNG-devel 3.0.0_3 upgrade hangs

    3
    0 Votes
    3 Posts
    462 Views
    RonpfSR

    When it hang like that during pkg install, wait maybe 10 minutes, restart Unbound from Services Tab.

    To prevent this from happening :

    Disable pfBlockerNG before doing the update Update pfBlockerNG Review pfBlockerNG settings Enable pfBlockerNG Force Reload All to be on the safe side.

    Who might have to synchronize your Groups with the Feeds tab.

  • maxmind -- do i need it for mysite?

    4
    0 Votes
    4 Posts
    478 Views
    johnpozJ

    @tross9 said in maxmind -- do i need it for mysite?:

    Outside the U.S. thus allowing outside the U.S. to possibly gain access. but I think that is Highly unlikely, only possible if a company goes out of business and their IP is sold.

    No that is not true at all - IPs are exchanged all the time.. Company does not have to go out of business. We recently sold off some IPs out of your /16, those IPs are now outside the US.

    What if company X has locations in countries A B and C.. And now is using some of their IP space in B vs A, etc.

    Geoip data is updated all the time. While it at first entry might just use the companies HQ that is in country X, at some point they determine that IP range xyz while owned by company in country A, is actually used in country B, etc..

    Lets be clear - the geoip database is a lets call it best guess at best ;)

    But if your concerned with only allowing IPs from XYZ via geoip data. Then it behooves you to make sure list of IPs your using is current. A maxmind account is free, while the data might not be perfect.. Using the current data is going to be more accurate then using old data.

    Even using the best and latest to the minute geoip data doesn't mean its correct.. If you are concerned with who can access your resource you have opened to the public. The best solution is to use their IPs, and only allow those.

    While I understand that can become problematic - especially with users that have no idea IP even is ;) If your concerned - get them to setup a ddns for their connection. Then use that ddns for your alias and only allow that.

    I do this for my son's connection. I manage his network remotely via his unifi devices (router and ap) being part of my controller... For that to happen they need to talk to my controller. I sure and the hell would not open my controller to the public internet, even I could limit the IPs to be on his block ;) let alone his city or country.. So I setup to only allow his IP, which sure changes now and then. So I use his ddns in the alias..

    iplist.png

    But for example my plex server - my users access this not only from their homes, but from their mobile devices.. It not really possible to know for sure what IP they might come from.. But I sure do not want to open that up to the whole internet. So I lock it down to only the countries they should be coming from.. So I use the listings for those.. Currently only US, but a buddies son was working in Honduras for a while - and so it was allowing US and Honduras, etc..

    The geoip listings can be useful.. But if the data is dated, its going to be less useful than current data.

    If my friends and family were more tech savy I would lock down their plex server access to only vpn access. But that is a pipe dream to expect normal users how to do that, and sure and the hell not going to spend the time to manage all of their devices and networks to use vpn to access my network. So I do atleast something to limit who can access my plex server. Be it far from perfect or optimally secure setup, etc.

    edit: Here I ran across this just a bit ago in my browsing.. This is perfect example of how things get messed up with geoip dbs
    https://www.reddit.com/r/networking/comments/k61a5j/geolocation_issue/

    The NL company has a location in the US, they got a line in the US and IP from the isp - but for some reason this ip is showing from the NL for geoip, etc..

    This sort of thing happens all the time - and yes it can be a real pain the ass to get corrected.. I had a /24 from our /16 that was showing up as being from vietnam... Tried for months to get it corrected.. That IP range had never been used in vietnam, and clearly anyone doing a simple traceroute could see it was in florida..

    It was causing issues with users accessing some stuff that was doing geoip filtering, like banks and stuff..

    Just more example of why if you want to do geoip filtering, there will be mistakes in the db. And you should use current a db as possible.

  • The domain is not listed in DNSBL!

    2
    0 Votes
    2 Posts
    233 Views
    M

    So I solved it myself. Turned off "keep settings", uninstalled and reinstalled pfblocker, making sure to delete the DNSBL default packages before running my first force reload.

  • New update but wrong link to release notes??

    1
    0 Votes
    1 Posts
    110 Views
    No one has replied
  • DNSBL to Syslog?

    3
    0 Votes
    3 Posts
    530 Views
    NogBadTheBadN

    Use the cron package.

  • Route for DNSBL VIP through site to site OpenVPN tunnel

    1
    0 Votes
    1 Posts
    126 Views
    No one has replied
  • devel 3.0.0/_1 Error loading rules.debug

    1
    0 Votes
    1 Posts
    127 Views
    No one has replied
  • pfBlockerNG and Chrome

    10
    0 Votes
    10 Posts
    1k Views
    D

    @ihavealegohead: Yes, I know about the Chrome settings, but I am more concerned with dealing with this globally, not browser by browser. Also with my IoT devices that hardwire access (e.g. 8.8.8.8 over HTTPS). It seems I've gotten rid of the last of those devices, since a floating rule I put in place to detect HTTPS connections to DNS servers is no longer getting hits.

    As for pfBlocker displaying a secure page: if it blocks an HTTPS page, your browser will never show it to you. The certificate in use at that moment is an internal pfBlocker cert, while the browser is expecting to see a certificate for the domain name you entered (while it is asked to show the internal pfBlocker SITE BLOCKED page). Ergo there will always be a certificate mismatch.

  • DNSBL doesn't work

    4
    0 Votes
    4 Posts
    535 Views
    GertjanG

    Actually, some thinking on my side was needed ;)

    @Abdulkarim said in DNSBL doesn't work:

    [ DNSBL FAIL ] [ Skipping : Social ].

    Do you see this message in an pfBlocker 'update log' ?
    Doesn't this mean that the download of feed that implements social blocking failed ? Which would explain the non blocking.

    Can you give more info / context ?

  • Phishtank list download fail

    35
    0 Votes
    35 Posts
    2k Views
    R

    @provels Thanks, I may update the version. I know that the author recommends the devel version for a long time, but for me this always sounded too much like "beta". Cheers!

  • 0 Votes
    1 Posts
    191 Views
    No one has replied
  • High CPU from lighttp_pfd

    3
    0 Votes
    3 Posts
    196 Views
    infosamu.itI

    @provels said in High CPU from lighttp_pfd:

    .malwarebytes.com

    thank you very much!
    also in my case your suggestion solved the issue.

  • pfblocker on a bridge interface

    1
    0 Votes
    1 Posts
    123 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.